1. Scope and data controller
Hangzhou Youyoumi Apparel Co., Ltd. (杭州优优米服饰有限公司) operates youyoumi.asia and is responsible for the personal information described in this policy. This policy covers the public website, contact form, and access-controlled company systems.
2. Information we collect
We may collect information you submit, including name, business email, company, shop context, and inquiry details. For security, our systems may record IP-derived security identifiers, browser information, timestamps, authentication events, and audit logs. Authorized operational systems may contain shop, product, order, creator, content, inventory, and performance data provided by or accessed for an authorized business.
3. Platform and API data
Where a seller or account owner authorizes platform access, we process only the information needed for the agreed service and within the permission granted. We do not ask users to publish credentials on this website. Access tokens, seller identifiers, shop emails, and confidential performance data are not displayed publicly.
4. How information is used
Information is used to respond to inquiries, plan and deliver agreed services, operate and secure authorized systems, prevent abuse, maintain business records, and meet legal or platform obligations. We do not sell platform or client data.
5. Sharing and processors
Information may be handled by authorized team members and necessary infrastructure providers under confidentiality and security controls. We may disclose information when required by law or to protect rights, security, and users. We do not share confidential seller data for unrelated advertising.
6. Retention and deletion
We retain information only for the agreed service, security, accounting, or legal purpose. Following service termination or valid authorization revocation, eligible active customer and platform data is deleted or irreversibly anonymized within 30 calendar days. Residual backup copies age out within 90 calendar days. Records that must be retained by law or for a documented legal claim are isolated, access-restricted, and deleted when that requirement expires.
7. Security and access control
Operational systems use authenticated, role-based access, least-privilege review, encrypted transport, secure cookies, audit and service logs, and managed infrastructure safeguards. Platform access tokens persisted by the application are encrypted with AES-GCM. Cloudflare-hosted object data is encrypted at rest. No system can guarantee absolute security, so suspected incidents must be reported promptly.
8. Data locations and international processing
Primary application storage is placed in Cloudflare's Asia-Pacific region. Authorized personnel may process data from China, and Cloudflare's global network may process traffic in other jurisdictions. Transfers are limited to the agreed purpose and protected by contractual, access, and security measures; mandatory local rights continue to apply.
9. Rights, requests, and incidents
For access, correction, portability, deletion, authorization revocation, or a suspected data incident, email chuan@youyoumi.asia. Include enough information to verify identity and authority. We aim to acknowledge requests within 5 business days and complete valid requests within 30 calendar days, subject to applicable law and any permitted extension. Confirmed incidents are communicated without undue delay as required by law and contract.